Google Cloud and Cybereason made good on their joint extended detection and response (XDR) promise this week.
To kick off its first annual DefenderCon event, the cybersecurity vendor launched Cybereason XDR powered by Google Chronicle.
“The reason that this is big is because we’re finally able to really deliver on that promise of finding and stopping attacks wherever they go across the environment,” said Eric Sun, product director for XDR at Cybereason.
XDR is a newish-technology that combines elements of security information and event management (SIEM); security orchestration, automation, and response (SOAR); endpoint detection and response (EDR); and network traffic analysis (NTA) in a software-as-a-service (SaaS) platform to centralize security data and incident response.
The new product combines Cybereason’s XDR platform, which fuses endpoint telemetry with behavioral analytics, with Google Cloud’s security analytics platform Chronicle.
The latter adds SIEM and SOAR capabilities, which Cybereason’s XDR platform lacks. The service is built on Google infrastructure, which ingests and analyses petabytes of data from across organizations’ entire IT infrastructure. This means it pulls threat data from not only Google Cloud and Google Workspace, but also from Microsoft environments.
“The Google chronicle technology allows us to integrate and understand data from email, and we’re seeing a slew of attacks there,” Sun said.
Faster Time to ResponseCybereason’s artificial intelligence (AI) technology gives its XDR a boost in an increasingly crowded playing field, he added. This includes its Cybereason MalOp, which analyzes over 23 trillion security events per week and provides detection and incident response in real time.
“It’s not just about the ingesting the data — that’s what a lot of systems do,” Sun said. “It’s that guided response and the predictive attack sequences that we're able to bring."
Sun says MalOp’s automated and guided response actions not only reduce human error, but also help analysts achieve a 10-times faster time to response than competing products from CrowdStrike, Sentinel One, and others.
Additionally, Chronicle allows analysts to map incident intelligence to retrospective data to find persistent threats across their environments. And Cybereason’s behavioral analytics helps security operations teams predict attacker behavior and proactively block attacks.
“So really combining the two allows us to extend our coverage to the security stacks that our customers have,” Sun said.
Google, Cybereason Join Crowded XDR PartyCybereason, which started as an endpoint detection and response (EDR) vendor, rolled out its XDR platform about a year ago. While it doesn’t have in-house SIEM and SOAR, its XDR focused on what it does best: detection, response, and proactive threat hunting. And it extends these capabilities from the endpoints across the enterprise IT environment spanning on premises, clouds, and mobile.
“Cybereason is taking what they’ve done well, which is having a deep understanding of activities on endpoints and expanding into other environments,” IDC Research VP Michael Suby said in an earlier interview.
Google Cloud moved into the XDR space more recently. At its Cloud Next event in October, the company announced XDR partnerships with CrowdStrike, Palo Alto Networks, and Cybereason.
While the XDR platform with Cybereason is the first jointly engineering product to come out of these partnerships, in May Google Cloud and CrowdStrike announced a deal to share telemetry and data between Google Cloud’s security products and CrowdStrike’s Falcon platform. At the time, Google VP of Cloud Security described it as “beyond XDR.”
Additionally, Palo Alto Networks has a longstanding partnership with the cloud giant. Just last week Google released Cloud IDS, a network-based threat detection based on Palo Alto Networks’ technology.
Comments